๐ช๐ธ
el-brujo
2026-09-02 05:12:53
(1 month ago)
5.181.131.240 - - [02/Sep/2026:07:12:51 +0200] "GET /student-registration HTTP/2.0" 404 15889 "https ...
show more
5.181.131.240 - - [02/Sep/2026:07:12:51 +0200] "GET /student-registration HTTP/2.0" 404 15889 "https://elhacker.net/geolocalizacion.html" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
5.181.131.240 - - [02/Sep/2026:07:12:52 +0200] "GET /student-registration HTTP/2.0" 404 15889 "https://elhacker.net/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
5.181.131.240 - - [02/Sep/2026:07:12:53 +0200] "POST /student-registration HTTP/2.0" 404 15889 "https://elhacker.net/student-registration" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Hacking
Anonymous
2026-08-14 00:39:17
(1 month ago)
Attempted search for exploits and vulnerabilities detected by fail2ban
...
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-13 16:13:40
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 12:13:31.338150 2026] [security2:error] [pid 31034:tid 31034] [client 5.181.131.240:28363] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hanabritgermanshepherds.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hanabritgermanshepherds.com"] [uri "/"] [unique_id "an3tK1uODsuTIdDRRAY2fQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-11 06:47:45
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 08:49:56
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 04:49:50.171582 2026] [security2:error] [pid 670237:tid 670237] [client 5.181.131.240:38335] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||frenchla.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "frenchla.com"] [uri "/"] [unique_id "anmQrteBq6UnXjToF5eHKgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-08 13:01:46
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 19:11:51
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 15:11:37.752874 2026] [security2:error] [pid 26510:tid 26510] [client 5.181.131.240:49309] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.creertest.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.creertest.com"] [uri "/student-registration"] [unique_id "anYt6fu3a-l76FgD9Pa6lQAAAAA"], referer: http://www.creertest.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2026-07-31 04:33:48
(2 months ago)
CMS vulnerability/installation scanning
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 09:26:24
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 05:26:18.503568 2026] [security2:error] [pid 17197:tid 17197] [client 5.181.131.240:45505] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.blacksheepoffroad.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.blacksheepoffroad.com"] [uri "/"] [unique_id "alSvOqGw2bcCHKtwIecmmQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-28 23:15:03
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-15.5.181.131.240.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-15.5.181.131.240.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 02:53:52
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.131.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:53:48.936286 2026] [security2:error] [pid 11077:tid 11100] [client 5.181.131.240:57797] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.siriuspharmaceuticals.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.siriuspharmaceuticals.com"] [uri "/products"] [unique_id "ajyYPGBbQWGrXSj4Dn4uhQAAANU"], referer: https://www.siriuspharmaceuticals.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-10 15:02:12
(3 months ago)
IM360 WAF: Block URI containing malicious URLs
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-05 08:47:00
(3 months ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-04 02:38:00
(4 months ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-01 08:57:00
(4 months ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack